LastPass Fallout and the Ensuing $716M Crypto Chaos
From law firms to universities, and from non-profits to manufacturers—password managers have become a foundational piece of your cybersecurity recipe. If you are, or have used, the consumer favorite LastPass, listen up. At CyberStreams, we’ve been tracking a cybersecurity saga that’s still unfolding: the LastPass breach of 2022. It’s not just a tech glitch—it’s a multimillion-dollar wake-up call, and it hit businesses and crypto bros hard.
Back in 2022, LastPass—the name in password managers which has had continual issues since being purchased by private equity—got hit hard. Hackers swiped encrypted vaults for 25 million users, including sensitive “Secure Notes” where folks stashed crypto currency keys. Fast forward to January 2024: Chris Larsen lost 283 million XRP, worth $150M then and a staggering $716M now, thanks to XRP’s price surge. The FBI and Secret Service tied it to those stolen LastPass vaults—cracked by hackers exploiting weak master passwords from early adopters. At this point the FBI has clawed back $23M, but most of Larsen’s haul is still out there, laundered across exchanges like Binance and Kraken.
This isn’t a one-off. By May 2024, the Security Alliance pegged LastPass-related crypto losses at $250M+, with $45M more snatched by December. Why? LastPass didn’t bump up encryption iterations for older accounts, leaving them ripe for brute-force attacks—some cracked in hours. For SMBs storing donor data, client files, or IP, it’s a red flag: lax security can cost you big.
Legal firms guarding case details, universities with student records, non-profits with donor lists, manufacturers with trade secrets—you’re not crypto moguls, but you’ve got assets hackers crave. A 2024 Verizon DBIR stat says 60% of breaches involve stolen credentials. If your team used LastPass for passwords—or worse, crypto keys—this breach’s ripple effect could hit you. Larsen’s loss shows even high rollers aren’t immune; imagine a non-profit losing donor trust or a factory leaking designs. CyberStreams has tracked LastPass’s ongoing security mishaps since its acquisition in 2020, and have made the decision not to offer this solution as a part of our Business Technology Optimization Platform.
We’ve been on this since day one, advising clients to use a more secure and business focused solution. Larsen’s $23M recovery is a win, but with $4.5M average breach costs, prevention beats cleanup. Our mission is to keep our clients secure—whether it’s a Austin law office or a Seattle aerospace plant—this is what drives us.
I've put together three takeaways and next steps:
1. Swap Your Manager
Ditch LastPass for a business class password manager.
2. Monitor for Breached Credentials
Monitor the dark web to be alerted if any of your company credentials are being sold by the bad guys.
3. Run a Breach Check
Book a CyberStreams audit—see if old LastPass use left your credentials exposed.
Link to original story: https://cyberstreams.com/blog/b/lastp...